Inspiration

Modern Security Operations Centers (SOCs) suffer from extreme alert fatigue—analysts face thousands of daily warnings, with false positive rates exceeding 70%. Real threats often drown in the noise, leading to delayed responses and burnout. We were inspired by the idea of an AI "co-pilot" that doesn't just flag anomalies, but actively thinks like a tier-3 analyst. We envisioned ThreatPulse: a system that reads raw telemetry, understands adversarial tactics, and delivers actionable intelligence in plain English, slashing Mean Time to Detection (MTTD) from hours to minutes.

What I Learned

This project was a deep dive into the intersection of Generative AI and Cyber Defense.

  • Prompt Engineering is critical: Designing few-shot prompts with MITRE ATT&CK context dramatically improved the LLM's ability to map events to specific TTPs (Tactics, Techniques, and Procedures).
  • Data normalization is the hidden bottleneck: SIEM logs vary wildly across vendors. We learned to build a lightweight parsing layer that extracts unified fields (source IP, user, action) before feeding the LLM.
  • Explainability is non-negotiable: For a SOC analyst to trust an AI verdict, the system must provide audit trails. We implemented a reasoning-chain logger that justifies every action, satisfying compliance requirements like GDPR and HIPAA.
  • Mathematically, we optimised the risk prioritisation formula: $$ \text{Risk_Score} = \text{CVSS_Base} \times \text{Business_Criticality} \times \text{Confidence_LLM} $$ where $$ \text{Confidence_LLM} $$ is derived from the model's token probability distribution over the predicted attack class.

How I Built It

We built ThreatPulse as a modular, cloud-native microservice:

  • Data Ingestion: Used Apache Kafka to stream live logs and Elasticsearch for historical querying.
  • Core Intelligence: Deployed a quantised Mistral-7B model via Ollama to ensure on-premise data privacy (no sensitive logs leave the customer's network). We used LangChain for agentic orchestration, connecting the LLM to a vector database (Pinecone) containing CVE descriptions and exploit databases.
  • Backend: FastAPI (Python) handles RESTful endpoints and webhook integrations with Slack and Jira.
  • Frontend: Built a real-time dashboard with React and D3.js to visualise attack chains as interactive kill-chain graphs.
  • Automation: The system generates Python scripts via the LLM to run specific firewall block commands (validated in a sandbox) and pushes them to the EDR (Endpoint Detection and Response) tool.
# Example logic flow
def triage_alert(raw_log):
    entity = extract_entities(raw_log)
    context = retrieve_similar_incidents(entity)
    prompt = build_prompt(entity, context)
    decision = llm.invoke(prompt)
    if decision.confidence > 0.85:
        execute_playbook(decision.action)
    return decision

Built With

Share this project:

Updates

Submission history